Nexa People holds payroll, national identity numbers and attendance for entire workforces, so this page states what is actually in place — and, just as deliberately, what is not.
Tenant isolation
Nexa People is multi-tenant: every organization's data — employees, payroll, attendance, settings — belongs to exactly one organization and is scoped to it on every request. One customer's users cannot reach another's data, even though they share the same platform.
Access control
Access inside an organization is governed by role tiers and permission templates that the employer configures, down to individual forms and actions. Sign-in is gated on the account being active and the employee not being terminated.
Our own access to customer data is limited to what running and supporting the service genuinely requires.
Encryption in transit
Traffic between you and the platform is encrypted in transit using TLS, terminated at our edge with certificates issued by Let's Encrypt.
If your security review needs detail on encryption at rest, key management or data residency, ask us and we will tell you exactly what is and is not in place today rather than answer with a checkbox. We would rather lose a box-ticking exercise than pass one on a claim we cannot evidence.
Audit logging
Privileged and business-significant actions are written to an audit log, along with sign-in events and IP addresses — both so we can investigate misuse and so employers have the trail their own compliance requires.
Biometric data stays on your device
Where you connect a biometric terminal, fingerprint and face templates stay on that device. Nexa People receives a numeric punch code and a timestamp — never the template itself.
What we do not claim
We hold no ISO 27001 or SOC 2 certification today, and we do not publish an uptime figure we have not measured. When either changes, it will appear here with its evidence rather than in a sales deck.
Reporting a vulnerability
Responsible security research is welcome. Write to [email protected] before testing and we will agree scope with you; we will not pursue good-faith research that follows what we agree. If a breach affects personal data, we notify affected customers without undue delay and support their own reporting duties.